CVE-2024-10366
20.03.2025, 10:15
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.Enginsight
Vendor | Product | Version |
---|---|---|
librechat | librechat | 0.7.5:rc2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration